🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9e1b3ad63e5da5c756495d8f2dbddb7ff783b2f4013ed4fc6c6b32c217a91d0b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA 9 File information Comments

SHA256 hash: 9e1b3ad63e5da5c756495d8f2dbddb7ff783b2f4013ed4fc6c6b32c217a91d0b
SHA3-384 hash: 5040dcba76afe4a5cef3c648f917803b6cee2555a98533a94468d11a7551444f36e4c7f1d2454ba25f409760a94ab811
SHA1 hash: f5899295942f8fc7ecebc47409317abdc70a9ccf
MD5 hash: 57afb794ff4480e0d11280d600aa1834
humanhash: item-wolfram-charlie-hotel
File name:V5-Loader.jar
Download: download sample
File size:4'219'051 bytes
First seen:2026-09-29 15:39:54 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:V5F3H3rnEhHTKfysSe13f/W+qh+mqUKeXpLZZv:VzEtnjex+/qUtLZx
TLSH T12916D167B3095573F7D1C13A52A28341FB3050693B47A547B9B8880D2FCBB602A763EE
TrID 48.2% (.JAR) Java Archive (13500/1/2)
37.5% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
14.2% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter james_pre
Tags:jar


Avatar
james_pre
Part of a malware campaign distributed via Github releases:
https://github.com/taunahi-org/taunahi-macro (taunahi-4.2.jar)
https://github.com/victormtz06/V5-Macro (V5-Loader.jar)
https://github.com/weldtrailclaim/mbf-skyblock-macro (mbf-release.jar)

C2: hxxp://31.77.8.137:5000

A second stage is pulled down containing a malicious libcurl.dll which is used in DLL poisoning of a Main.exe.

Intelligence


File Origin
# of uploads :
1
# of downloads :
7
Origin country :
US US
Vendor Threat Intelligence
No detections
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:JAR_Network_Indicators_Detection
Author:TheKn0ck0ut
Description:Detects JAR file info by hash
Rule name:JAVA_Malware_Unknown_ForgeAuto_0ece8eba
Author:Marjoriefort
Description:Detects Unknown (class, etat binaire)
Rule name:JAVA_Malware_Unknown_ForgeAuto_6c4b5896
Author:Marjoriefort
Description:Detects Unknown (class, etat binaire)
Rule name:JAVA_Malware_Unknown_ForgeAuto_90eece6c_Extrait
Author:Marjoriefort
Description:Detects Unknown (class, etat extrait)
Rule name:MULTI_Malware_Unknown_ForgeAuto_6dc545a6
Author:Marjoriefort
Description:Detects Unknown (inconnu, etat binaire)
Rule name:MULTI_Malware_Unknown_ForgeAuto_b2a4008d
Author:Marjoriefort
Description:Detects Unknown (inconnu, etat binaire)
Rule name:RANSOMWARE
Author:ToroGuitar

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Java file jar 9e1b3ad63e5da5c756495d8f2dbddb7ff783b2f4013ed4fc6c6b32c217a91d0b

(this sample)

0be4a64fa3aa5ee600424244e62a197322d3c7401b2dae57bc84de7fda83faea

  
Dropping
SHA256 0be4a64fa3aa5ee600424244e62a197322d3c7401b2dae57bc84de7fda83faea
  
Delivery method
Distributed via web download

Comments